Security Researcher (Multiple Positions)
Core
Apply attacker methodology frameworks to contextualize threats, assess progression, and determine potential impact of identity-centric and cloud-based attacks.
Role type
Security Researcher (Threat Analysis & Investigation)
Builds
Customer-facing investigation summaries and defensible evidence for security incidents.
Domain
Cybersecurity, Threat Intelligence, Cloud Security
Required skills
MITRE ATT&CK Framework, Cyber Kill Chain, Kusto Query Language (KQL), OS internals (Windows, Linux, Mac), identity misuse investigation, cloud telemetry analysis (Azure, AWS, GCP), offensive security tools (Metasploit, OSINT), pattern recognition, critical thinking
Preferred skills
Experience with OAuth abuse, token theft, Kerberos/NTLM anomalies, conditional access bypass patterns, exploit development
Technologies
KQL, Metasploit, Azure, AWS, GCP, Windows, Linux, Mac
Responsibilities
Investigate identity centric threats, credential misuse, lateral movement, and cloud-based attacks; Correlate large datasets to uncover relationships and root cause; Differentiate benign, misconfigured, suspicious, and malicious activity; Deliver customer facing investigation summaries; Perform investigations involving authentication anomalies and suspicious access patterns
Seniority
Mid-level (2+ years experience) to Senior (1+ years with Master's)